cisaregulatorNewsThe Broadside1 min read

CISA adds SharePoint flaw CVE-2026-45659 to KEV

For federal teams, the practical instruction is simple: find exposed SharePoint, patch fast, then check whether attackers got there first.


TL;DR

CISA added CVE-2026-45659, a Microsoft SharePoint Server deserialization of untrusted data vulnerability, to the Known Exploited Vulnerabilities Catalog based on active exploitation. Federal Civilian Executive Branch agencies must prioritize KEV vulnerabilities under Binding Operational Directive 26-04, especially on publicly exposed assets that allow total control after exploitation. Contractors, managed service providers, and C3PAOs supporting federal systems should treat the listing as immediate remediation pressure, even though BOD 26-04 applies only to FCEB agencies.

CISA’s July 1 KEV update is a routine catalog move, not a new rule. The agency added CVE-2026-45659, a Microsoft SharePoint Server deserialization vulnerability, based on evidence of active exploitation. Under Binding Operational Directive 26-04, Federal Civilian Executive Branch agencies must prioritize rapid remediation of KEV-listed vulnerabilities on publicly exposed assets that grant total control after exploitation, and must account for whether the system was compromised before patching. For contractors, managed service providers, and C3PAOs, the directive is not written as a contractor enforcement regime. The operational answer is still the same: exposed SharePoint in or near a federal environment should move to the top of the patch queue.


Published ·Deep Fathom